Verified reproduction
REPRO-2026-00319: MariaDB Galera SST remote_auth shell command injection (wsrep_shell_char blacklist bypass) — candidate for v12sec 2026-07-31 0day
REPRO-2026-00319 is verified against MariaDB/server · github vulnerability class: Command Injection This critical reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00319.
Severity CRITICAL
Confidence HIGH
Reproduced in 84m 16s
Tool calls 463
Spend $41.26
$
pruva-verify REPRO-2026-00319 or
curl -O https://pruva.dev/api/v1/reproductions/REPRO-2026-00319/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Run in a VM or disposable container. This exploits a real vulnerability.
Candidate MariaDB Galera donor-side command injection through joiner-controlled SST remote_auth reaching shell SST scripts.
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Loading session...
Scripts, logs, diffs, and output captured during the reproduction.
bundle/logs/fixed_donor.log0.8 KBbundle/logs/fixed_joiner.log0.1 KBbundle/logs/product_linkage.log1.6 KBbundle/logs/reproduction_steps.log1.2 KBbundle/logs/source_identity.log0.6 KBbundle/logs/vulnerable_donor.log23.1 KBbundle/logs/vulnerable_joiner.log20.8 KBbundle/repro/donor_command_marker.txt0.0 KBbundle/repro/rca_report.md9.1 KBbundle/repro/reproduction_steps.sh15.3 KBbundle/repro/runtime_manifest.json2.2 KBbundle/repro/validation_verdict.json0.9 KB